Skip to content
KnowledgeCity

By KnowledgeCity

Why Banks Need Fraud Red Flag Training for Tellers and Frontline Staff

12 min read

Bank branch teller holding customer documents, beside a grayscale photograph of a branch teller counter

Key Takeaways

  • Bank tellers are the first people to spot fraud, and federal rules require banks to train them.
  • FTC data shows consumers reported $12.5 billion lost to fraud in 2024, with older adults reporting $2.4 billion of that.
  • Financial institutions filed 4.7 million Suspicious Activity Reports in fiscal year 2024, most triggered by frontline observations.
  • The Identity Theft Red Flags Rule and the BSA/AML rule both require documented training for staff who open accounts and handle transactions.
  • Effective frontline fraud training pairs current FinCEN advisory content with an audit-ready record of who was trained, when, and on what.

Bank fraud does not start in the compliance office. It starts at the teller window, the new-account desk, and the drive-through. A teller who spots an anxious 82-year-old customer withdrawing $9,500 in cash "for a family emergency" catches a scam that a monthly AML review would find 3 weeks later, after the money is gone.

That first-line role is now a regulatory expectation. FinCEN's 2022 elder financial exploitation advisory, the December 2024 interagency statement on the same subject, the Identity Theft Red Flags Rule under 12 CFR Part 41, and the BSA/AML training requirement at 31 CFR 1020.210 all point the same direction. Banks are expected to train frontline staff on the specific red flag patterns their examiners and FinCEN advisories describe, and to document that training in a record examiners can review.

This article walks through the fraud environment tellers see today, the regulatory framework that makes frontline training an obligation, where community and regional bank training programs typically fall short, and what an effective fraud red flag training program actually covers.

The Fraud Environment Frontline Bank Staff Face Today

The volume and pattern of fraud coming across the teller line has shifted every year for the past 5, and 2024 was the largest single-year escalation on record.

The Fraud Loss Numbers Regulators Are Watching

Consumers reported losing $12.5 billion to fraud in 2024 per the FTC Consumer Sentinel Network. Older adults (ages 60 and above) accounted for $2.4 billion of that, up roughly fourfold from about $600 million in 2020. Accounting for underreporting, the FTC puts the real cost to older adults in 2024 somewhere between $10.1 billion and $81.5 billion. Investment scams, business impersonation, and government impersonation were the top three fraud categories for older adults, in that order.

Where SAR Filings Are Concentrated

Across all filer types, financial institutions filed 4.7 million Suspicious Activity Reports in fiscal year 2024, an average of about 12,870 per day. Depository institutions on their own, meaning banks, savings associations and credit unions, filed 2.193 million SARs in calendar year 2025, up 7.66% over their own 2024 total. Elder financial abuse SAR filings jumped 9.7% year over year, reaching 171,233 in 2024. Check fraud SARs held near the record with 682,276 filings in 2024, and remain among the top categories despite growing sophistication in wire and instant-payment fraud.

The Federal Rules That Make Frontline Fraud Detection an Obligation

Banks are supervised on their fraud detection program the same way they are supervised on capital and lending. Four regulatory anchors sit under frontline fraud training.

Frontline Fraud Red Flags Mapped to Regulatory Source

Red flag category

Example indicator a teller should notice

Source guidance

Elder financial exploitation

Unusual large withdrawals or wire transfers inconsistent with the customer's account history

FinCEN Advisory FIN-2022-A002; 2024 Interagency Statement

Check fraud

Altered payee lines, counterfeit checks, or repeated large deposits followed by rapid withdrawals

FinCEN SAR filings (top category, 2022 to 2024)

Identity theft and new-account fraud

Address discrepancies, mismatched ID documents, or unfamiliar signatures

12 CFR Part 41 Subpart J (Identity Theft Red Flags Rule)

Wire and impersonation scams

Customer receiving urgent instructions from "IRS," "Social Security," or a "grandchild in trouble"

FTC Consumer Sentinel 2024 data; FinCEN advisories

Structuring

Multiple deposits or withdrawals just under the $10,000 CTR threshold

31 CFR 1010.311 (Currency Transaction Report); 31 CFR 1010.100(xx)

Suspicious source of funds

Cash deposits with no apparent business or lawful purpose

31 CFR 1020.320 (SAR Rule)

31 CFR 1020.210 and the BSA/AML Training Requirement

The core AML program rule at 31 CFR 1020.210, implementing 31 USC 5318(h), requires every bank to establish a written AML program that includes training for appropriate personnel. The statute calls for that training to be ongoing, and the FFIEC BSA/AML Examination Manual asks that periodic training keep pace with current developments, which most banks operationalize as yearly BSA/AML training. Training must be scaled to the employee's role, so a teller's training covers different red flags than a wire-transfer clerk's or a lending officer's.

12 CFR Part 41 Identity Theft Red Flags Rule

The Identity Theft Red Flags Rule at 12 CFR Part 41 Subpart J requires OCC-supervised national banks and federal savings associations to establish a written Identity Theft Prevention Program. The rule implements Section 114 of the Fair and Accurate Credit Transactions Act of 2003 (FACT Act). Appendix J to Part 41 contains the interagency guidelines identifying patterns and practices that indicate identity theft. The program must include training for staff to effectively implement it. Parallel rules apply to Federal Reserve state member banks and FDIC-supervised state non-member banks.

FinCEN Advisories and the Elder Financial Exploitation SAR Category

FinCEN Advisory FIN-2022-A002 (June 15, 2022) identified elder financial exploitation red flags for financial institutions to detect and report. The December 2024 interagency statement, joined by FinCEN and federal banking regulators, reinforced the expectation that banks train staff on EFE indicators. FinCEN's SAR form carries a dedicated check box for elder financial exploitation at Field 38(d), which is why the category's filing volume is a measurable enforcement signal.

The SAR Filing Chain from Teller to Compliance Officer

Why Banks Need Fraud Red Flag Training for Tellers. The Numbers a Teller Works To $10,000 The currency transaction report threshold that structuring stays under 30 calendar days SAR filing deadline from initial detection 60 days The maximum, and only where no suspect has been identified 171,233 Elder financial exploitation SARs filed in 2024

The teller does not file the SAR. What the teller does is escalate the observation to the BSA officer, in the form the bank's procedures require, within the internal deadline that lets the compliance team meet FinCEN's 30-calendar-day filing window (60 days if no subject is identified). A missed escalation at the teller line usually means a missed SAR filing, and a missed SAR filing shows up in the next examination.

Where Fraud Red Flag Training Typically Falls Short

The training exists. Examiners still find gaps. Four patterns show up on nearly every community and regional bank exam where the fraud program gets criticized.

Generic Annual BSA/AML Training Skips the Teller Line

The annual BSA/AML course is usually built for the whole bank. It covers structuring, currency transaction reports, and the basics of SAR filing. It rarely covers what a teller specifically should notice about a checking-account withdrawal at 4:45 PM on a Friday from a customer who has never done that before.

New-Hire Training Does Not Match the Current Threat Roster

Onboarding modules were often written 2 or 3 years ago and have not been refreshed against the current FinCEN advisory language. A new teller in 2026 needs training that names 2025 impersonation-scam patterns and 2024 elder-exploitation indicators, not 2022's.

Refresher Cycles Lag Behind FinCEN Advisory Updates

FinCEN issues advisories on a rolling basis. Banks that refresh training only on an annual calendar cycle can go 8 or 9 months between an advisory publication and the training update that reflects it. That gap is where the fraud lands.

Documentation Does Not Prove Teller Competency

The bank has completion records for the annual course. It does not have evidence that each teller can actually recognize the red flags the course covered. The examiner's follow-up question, "how does the bank confirm frontline staff can identify these patterns in practice," does not resolve with a completion certificate.

What Effective Fraud Red Flag Training for Tellers Covers

The training that holds up in an examination and reduces fraud losses is structured, role-specific, and updated as advisories change. Five content areas are the operational core.

Elder Financial Exploitation Indicators

Tellers learn to notice unusual withdrawal patterns, unfamiliar caregivers or "helpers" accompanying the customer, urgent instructions the customer says came from a family member or agency, and confusion or hesitation that is inconsistent with the customer's usual behavior. The training also covers the internal escalation path to the BSA officer and the SAR narrative language FinCEN's advisory recommends.

Check Fraud and Counterfeit Instrument Patterns

Tellers learn to inspect for altered payees, mismatched signatures, unusual paper stock, missing security features, and repeated deposits of the same amount from the same payer that clear before the deposit is verified. Training covers the recent uptick in mail-theft-driven check fraud that peaked in the 2022 to 2024 window.

Identity Theft and New-Account Red Flags

Tellers and new-account personnel learn to identify address discrepancies, ID documents that do not match the applicant, signatures that differ across documents, and inconsistencies between the application and the supporting materials. The training maps directly to the Identity Theft Prevention Program the bank has established under 12 CFR Part 41.

Wire and Impersonation Scam Signals

Frontline staff learn to identify the scripts scammers use to pressure customers into wire transfers. Common patterns are impersonation of the IRS, Social Security Administration, Medicare, or a family member "in trouble." The training covers how tellers pause the transaction, ask specific questions, and refer the customer to the branch manager or a fraud specialist.

SAR Escalation and Documentation

Tellers learn to write the observation in the language the BSA officer needs to produce a filable SAR narrative. That includes what the customer said, what documents were presented, the time and channel, and what the teller escalated to. The escalation form is standardized so the BSA officer receives the same structured input across branches.

How KnowledgeCity Supports Banking Fraud Red Flag Training

KnowledgeCity's workforce development platform runs the fraud training program across 3 solutions. KC Library holds the content. KC LMS delivers it and produces the audit-ready completion record. KC Docs carries the escalation procedures and policy acknowledgments the examination file needs.

What KC Library Delivers for Banking Content

KC Library contains 50,000+ training videos across job-specific and skills content. Its Finance category covers Regulations, Fraud Prevention, Retail Banking, Treasury, Finance and Investing, and Accounting Principles. For banks, KC Library organizes an AML/BSA/KYC training matrix per job code, so tellers, new-account clerks, branch managers, and executives each receive the modules their role requires. Content refreshes monthly, so the module a teller sees in the current quarter reflects current FinCEN advisory language.

What KC LMS Delivers for Assignment and Audit Records

KC LMS sits in the Learn suite and delivers the training with the audit-ready surface a BSA examiner expects:

  • Compliance and Assignment Engine: Rule-based, recurring assignments with an audit-ready trail across every branch and role.
  • Learning Paths and Curricula: Sequenced red flag training for tellers, new-account clerks, and branch managers.
  • Certification and Recertification: Automated issuance with expiry-based recertification aligned to the annual BSA/AML cycle.
  • Analytics and Integrations: Compliance dashboards, SSO, SCIM, HRIS, and webhooks so training records flow into the bank's compliance system.

What KC Docs Delivers for SOP and Acknowledgment

KC Docs sits in the Comply suite and carries the escalation procedures and SAR forms tellers rely on daily:

  • Versioned Policy Documents: Immutable versions of the internal SAR escalation form and red flag SOPs.
  • Read-and-Acknowledge: Formal, auditable attestation that each teller has read the current fraud SOP.
  • Automatic Re-Acknowledgment: Any FinCEN advisory-driven revision triggers a new signature.
  • Audit-Trail Export: Acknowledgment records on demand for the examination file.

What This Looks Like End-to-End for a BSA Officer

The BSA officer assigns the current fraud red flag curriculum to every teller through KC LMS. Tellers complete the modules and their completion attaches to the branch training record. Any FinCEN advisory update triggers a new SOP version in KC Docs, and every teller re-signs. When the OCC, FDIC, or Federal Reserve examiner asks how the bank trains frontline staff to detect fraud, the file is one export from the same environment that ran the training. For context on how the frontline training fits into a full-year compliance calendar, see inside a banking compliance officer's annual training calendar.

Frequently Asked Questions

1. What are fraud red flags in banking?

Fraud red flags are patterns or behaviors that suggest possible fraud, identity theft, or elder financial exploitation. Examples include unusual withdrawal patterns, altered checks, mismatched ID documents, or urgent wire transfer requests from customers who claim they are being contacted by the IRS or a family member. FinCEN advisories and 12 CFR Part 41 Appendix J list the specific patterns banks must train staff to notice.

2. What training does the BSA require for bank tellers?

31 CFR 1020.210 requires banks to include training for appropriate personnel in their AML program, the statute calls for that training to be ongoing, and most banks run it as a yearly BSA/AML course. Training must be scaled to the employee's role, so tellers receive content on frontline red flags, structuring below the $10,000 CTR threshold, and SAR escalation procedures.

3. What is the Identity Theft Red Flags Rule?

The Identity Theft Red Flags Rule at 12 CFR Part 41 Subpart J (for OCC-supervised banks, with parallel FRB and FDIC rules) requires financial institutions to establish a written Identity Theft Prevention Program. The program must detect, prevent, and mitigate identity theft in connection with covered accounts, and it must include staff training. Appendix J contains the interagency guidelines listing 26 specific red flag patterns.

4. How many SARs did banks file in 2024?

Across all filer types, financial institutions filed 4.7 million Suspicious Activity Reports in fiscal year 2024, an average of about 12,870 per day. Depository institutions on their own, meaning banks, savings associations and credit unions, filed 2.193 million SARs in calendar year 2025, up 7.66% over their own 2024 total. Elder financial abuse SARs alone reached 171,233 in 2024, up 9.7% year over year.

5. How much fraud loss did older adults report in 2024?

Older adults (60 and above) reported losing $2.4 billion to fraud in 2024 per the FTC Consumer Sentinel Network, roughly fourfold higher than the $600 million reported in 2020. Investment scams, business impersonation, and government impersonation were the top three loss categories. Accounting for underreporting, the FTC puts the real cost somewhere between $10.1 billion and $81.5 billion.

References

  1. Financial Crimes Enforcement Network. Advisory on Elder Financial Exploitation, FIN-2022-A002.
  2. Federal Financial Institutions Examination Council. BSA/AML Examination Manual.
  3. Code of Federal Regulations. 31 CFR 1020.210, Anti-Money Laundering Program Requirements for Banks.
  4. Code of Federal Regulations. 12 CFR Part 41 Subpart J, Identity Theft Red Flags.
  5. Federal Trade Commission. Consumer Sentinel Network Data Book 2024.
  6. Federal Trade Commission. FTC Data on Older Adults and Fraud, August 2025.
  7. Financial Crimes Enforcement Network. SAR Filings by Industry.

Everything your workforce needs, on one platform.

A quick walkthrough tailored to your team — learning, compliance, skills, and performance in one place.